CVE List

Id CVE No. Status Description Phase Votes Comments Actions
4267  CVE-2001-1464  Candidate  Crystal Reports, when displaying data for a password protected database using HTML pages, embeds the username and password in cleartext in the HTML page and the URL, which allows remote attackers to obtain passwords.  Assigned (20050421)  None (candidate not yet proposed)    View
4268  CVE-2001-1465  Candidate  SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements.  Assigned (20050421)  None (candidate not yet proposed)    View
4269  CVE-2001-1466  Candidate  Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arbitrary code via a long (1) username or (2) password.  Assigned (20050421)  None (candidate not yet proposed)    View
4270  CVE-2001-1467  Candidate  mkpasswd in expect 5.2.8, as used by Red Hat Linux 6.2 through 7.0, seeds its random number generator with its process ID, which limits the space of possible seeds and makes it easier for attackers to conduct brute force password attacks.  Assigned (20050421)  None (candidate not yet proposed)    View
4271  CVE-2001-1468  Candidate  PHP remote file inclusion vulnerability in checklogin.php in phpSecurePages 0.24 and earlier allows remote attackers to execute arbitrary PHP code by modifying the cfgProgDir parameter to reference a URL on a remote web server that contains the code.  Assigned (20050421)  None (candidate not yet proposed)    View

Page 19536 of 20943, showing 5 records out of 104715 total, starting on record 97676, ending on 97680

Actions